IBM Support

IBM Security Guardium: Vulnerability Assessment Issues "Must Gather"

Question & Answer


Question

What do I need to provide to IBM Support if I have an issue with a Gardium Vulnerability Assessment (VA)?

Cause

You have an error or failure that you need to resolve. You or your DBA has questions about the assessment.

Answer

Before you proceed, check that you are using the latest DPS (Data Protection Service). You must use the latest which is available on Fix Central.


In the Central Manager or unmanaged collector, use Harden > Vulnerability Assessment > Customer Uploads. In the DPS sections, you'll see the current version. Compare this version to the one on Fix Central. If you don't have the latest, then download it from Fix Central, upload to Guardium, and re-run the assessment.

If you still have a problem, open a PMR with IBM Support and submit the following:

1. Export the assessment report.

2. Get the jobqueue.log which is accessible from fileserver.
Scan the log for the date and time stamp of the report. Because other jobs write to this log, it may not have the date-time for when the report was run. In this case, re-run the assessment and immediately collect the corresponding jobqueue.log.

3. Get the latest gdmmonitor scripts for this database, also accessible via fileserver: Click on "Sqlguard logs". Under the /log/debug-logs/gdmmonitor_scripts/ directory, you will find all the scripts for all the different database types. For example, for an assessment of a DB2 database, look for the gdmmonitor-db2-*.sql scripts. Save those scripts and upload them. They should reflect your local corporate compliance rules.

4. Run the support "must gather" system_db_info for the appliance.

[{"Product":{"code":"SSMPHH","label":"IBM Security Guardium"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Guardium Database Vulnerability Assessment","Platform":[{"code":"PF016","label":"Linux"}],"Version":"10.0;10.0.1;10.1;9.5","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
16 June 2018

UID

swg21993963